Privacy Notice
EqualVoice-Assistant

1. Introduction

1.1. Ringier AG (“we,” “us,” or “our“) is committed to protecting your privacy. This Privacy Notice explains how we collect, use, disclose, and safeguard your personal data when you use our Service.

1.2. This notice is drafted to comply with the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).

 

2. Data Controller

2.1. The data controller responsible for your personal data is:

Ringier AG
Dufourstrasse 23
8008 Zurich
Switzerland
dataprotection@ringier.ch

 

3. Personal Data We Collect

3.1. We collect the following categories of personal data:

  1. Account Data: When you register, we collect your email address, first and last name, and company name. This information is mandatory for account creation.
  2. Content Data: We process the text, prompts, and other content you submit to the Service (“Input”) and the content generated by the Service (“Output”). This data may contain personal data, depending on what you choose to provide. The Service is not designed for sensitive or special category data.
  3. Usage and Telemetry Data: We automatically log technical information about your use of the Service, including requests, responses, processing times, your user ID, and timestamps.
  4. Financial Data: If you subscribe to a paid plan, your payments will be processed by our technical payment gateway provider, Datatrans, in cooperation with our acquiring partner, Worldline. We do not collect or store your full credit card details on our servers. Instead, we rely on a secure tokenization method. Our payment partners securely store and encrypt your payment data and provide us with a non-sensitive payment token to process recurring subscription fees. They process your data as independent data controllers in accordance with their respective privacy policies.

 

4. Purposes and Legal Basis for Processing

Purpose of Processing Categories of Data Legal Basis (GDPR / FADP)
To provide, operate, and maintain the Service. Account Data, Content Data Performance of a contract.
To manage your account and send administrative information. Account Data Performance of a contract.
To monitor and analyze usage for service security and stability. Usage and Telemetry Data Legitimate interest to secure our Service.
To improve our AI models and the Service internally. Content Data, Usage and Telemetry Data Legitimate interest to improve our Service, subject to your right to opt-out. For organizational/enterprise accounts, data is not used for this purpose without explicit consent.
To comply with legal obligations. All applicable categories Compliance with legal obligations.

 

5. Data Recipients and Sub-processors

5.1. We do not sell your personal data and/or content data. We may share your data with carefully selected third-party service providers (sub-processors who assists us in operating the Service. These sub-processors process personal data and/or content data solely on our behalf and in accordance with our documented instructions. They are not permitted to process such data for their own purpose or for any third party’s purposes.  

5.2. These include providers for cloud hosting (Amazon Web Services), AI model processing (Input/Output data) (OpenAI), and observability/logging (Langfuse).

5.3. A full, up-to-date list of our sub-processors is available in our Sub-Processor List. We have entered into adequate data processing agreements with all sub-processors.

 

6. International Data Transfers

6.1. Your personal data is primarily stored and processed within the European Union (Frankfurt, Germany).

6.2. However, some of our sub-processors (e.g., OpenAI, Amazon Web Services for certain operations) are based in the United States. When we transfer your data outside of Switzerland or the European Economic Area (EEA), we ensure appropriate safeguards are in place.

6.3. Such transfers are governed by adequacy decisions where applicable, or by the EU Standard Contractual Clauses (SCCs), as adapted to be valid for transfers under the Swiss FADP.

 

7. Data Retention

7.1. We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law.

7.2. For detailed information on our retention periods for different categories of data, please refer to our Data Retention Schedule.

 

8. Your Data Protection Rights

8.1. Depending on your location and applicable law, you may have the following rights regarding your personal data:

  1. Right of Access: To request a copy of the personal data we hold about you.
  2. Right to Rectification: To request correction of inaccurate or incomplete data.
  3. Right to Erasure (“Right to be Forgotten”): To request the deletion of your personal data under certain conditions.
  4. Right to Restrict Processing: To request the restriction of how we process your data.
  5. Right to Data Portability: To receive your data in a structured, commonly used, and machine-readable format. The Service provides a REST API (JSON format) for data export.
  6. Right to Object: To object to processing based on our legitimate interests.

8.2. To exercise any of these rights, please contact us at dataprotection@ringier.ch. We will respond to your request in accordance with applicable data protection laws.

 

9. Data Security

9.1. We implement robust technical and organizational measures to protect your personal data. This includes encryption of data in transit (TLS) and at rest, use of AWS Key Management Service (KMS), strict access controls based on the principle of least privilege, and management of secrets via AWS Secrets Manager. For more details, see our Annex on Technical and Organisational Measures (TOMs).

 

10. Cookies

10.1. We currently do not plan to use analytics or advertising cookies. For more information, please see our Cookie Policy.

 

July 2026

 


Annex: Data Retention Schedule

This schedule outlines the default retention periods for personal data processed by the Service.

Data Category Default Retention Period Trigger for Deletion Notes
Account Data (e.g., email, name) Duration of the contract + 90 days thereafter. Account closure + 90 days.
Invoices and financial records For the period required under applicable accounting and tax laws (10 years in Switzerland)  Expiry of the applicable statutory retention period. Includes only information required for accounting, tax and audit purposes. Payment data processed exclusively by payment providers is not retained by Ringier. 
Content Data (Inputs/Outputs) Max. 12 months from creation.  Customer-initiated deletion, account closure, or automatically upon reaching the 12-month threshold.  Content is retained to provide conversation history and contextual functionality. Use of content for model training, if any, is governed by a separate retention rule. 
Content used for Model Training (Input & Output)  Identifiable inputs and outputs: no longer than 90. Thereafter, the content is deleted or irreversibly anonymised. Anonymised or appropriately de-identified datasets may be retained for the duration of the relevant model-development and validation cycle.  Expiry of the applicable retention period; completion or discontinuation of the relevant development project; withdrawal or objection where applicable; or determination that the data is no longer necessary. Where applicable (not for business / organizational accounts) content may be used for model training. 
Audit Logs 12 months. Rolling deletion. Retention may be extended for security investigations.
Backups 35 days. Rolling deletion. Backups are encrypted.
Usage and Telemetry Data 12 months.  Rolling deletion or full anonymization After 12 months, data is either securely deleted or fully aggregated and anonymized so that it can no longer be linked to an identifiable user.

 

July 2026

Representing reality

Ready to elevate visibility and inclusion in your communication?

The EqualVoice-Assistant is now available.